From e7f3702d9b7e173b9c94aef76f72dd92a3294d44 Mon Sep 17 00:00:00 2001 From: Alan Guo Xiang Tan Date: Tue, 12 Apr 2022 12:28:23 +0800 Subject: [PATCH] SECURITY: Update Nokogiri to 1.13.4. Nokogiri 1.13.4 updates zlib to 1.2.12 to address CVE-2018-25032. https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v6gp-9mmm-c6p5 https://nvd.nist.gov/vuln/detail/CVE-2018-25032 --- Gemfile.lock | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index a34e2bcb9d1..8013009e0f2 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -247,16 +247,16 @@ GEM multipart-post (2.1.1) mustache (1.1.1) nio4r (2.5.8) - nokogiri (1.13.3) + nokogiri (1.13.4) mini_portile2 (~> 2.8.0) racc (~> 1.4) - nokogiri (1.13.3-aarch64-linux) + nokogiri (1.13.4-aarch64-linux) racc (~> 1.4) - nokogiri (1.13.3-arm64-darwin) + nokogiri (1.13.4-arm64-darwin) racc (~> 1.4) - nokogiri (1.13.3-x86_64-darwin) + nokogiri (1.13.4-x86_64-darwin) racc (~> 1.4) - nokogiri (1.13.3-x86_64-linux) + nokogiri (1.13.4-x86_64-linux) racc (~> 1.4) oauth (0.5.8) oauth2 (1.4.7)